I got reading some stuff as usual i ended up with some doubts ,so i decided to ask here,

I am sure most of the guys here knows about xsssqli

Similar to this is it possible to inject xss code through an sql injection?

While thinking about this it has raised some questions in my mind

1)say a web site is vulnerable to sql injection,is it possible to inject xss code in to the sql vulnerable part and make it vulnerable to xss ?

2)Also can we Introduce All the threee types of xss like persistent,non-persistent and DOM based with this ?

3)In general Assume if a web-application is vulnerable to sqli and xss means ,what are the other possible attackswe can introduce with those vulnerabilities (like CSRF etc)?

4)And if you like please say a few words about xss as a SERVER SIDE THREAT ,so that i can understand about it as a server side threat,because some of the ppl around me just thinks it as a client side vulnerability that can just damage to client side..

1) If you are able to execute insert/update statements. There obviously needs to be other flaws available as well (i.e. not encoding output), but this is certainly possible.

2) Think about various scenarios in which information from a database is dynamically used. Writing content and displaying a web page, sending marketing emails, generating links on the fly, etc. Magic Eight Ball says, "All signs point to yes"

3) In general, once you gain a foothold with any technology (web, wireless, systems, network, etc.), you can leverage it for other attacks. CSRF, LFI/RFI, command execution, and so on all become more likely once you identify a vulnerability.

If you can get a SQL error message that displays your input, then you might be able to provide a script tag as input to do XSS. However, this would require that the output isn't sanitized. More importantly, error messages tend to have a fixed length, so how much XSS you can inject would be limited.

manoj9372 wrote:I got reading some stuff as usual i ended up with some doubts ,so i decided to ask here,

I am sure most of the guys here knows about xsssqli

Similar to this is it possible to inject xss code through an sql injection?

While thinking about this it has raised some questions in my mind

1)say a web site is vulnerable to sql injection,is it possible to inject xss code in to the sql vulnerable part and make it vulnerable to xss ?

2)Also can we Introduce All the threee types of xss like persistent,non-persistent and DOM based with this ?

3)In general Assume if a web-application is vulnerable to sqli and xss means ,what are the other possible attackswe can introduce with those vulnerabilities (like CSRF etc)?

4)And if you like please say a few words about xss as a SERVER SIDE THREAT ,so that i can understand about it as a server side threat,because some of the ppl around me just thinks it as a client side vulnerability that can just damage to client side..

Bear with me

Im not sure about xsssqli but I do know if the sql injection is a ristricted area for a guest user to reach , you always can use XSS andf bit of javascript make a automated sql injection script and so the SQL Injection trough admin .here is a video tut ..http://www.youtube.com/watch?v=2b0VD4_rg8Q

1. Yes you can . if a page is vulnerable to SQL Injection , You can perform a XSS with SQL Injection . for a example

nytfox wrote:4. in to my knowledge you can't attack Server side with just XSS

Some notes about XSS:- XSS requires a client of some sort, to execute the cross-site script that's being used to attack with.- When XSS is reflected, it is not persistent and is therefore not stored server-side. When XSS is stored, it's persistent and is therefore stored server-side.- In order to attack server-side with XSS, a client must be included to execute the malicious script that the attacker created.- The actions that the XSS script do, can range from simple session hijacking, port scanning, etc., to CSRF attacks that abuses functionality of the website and e.g., injects PHP code into the application via features like templates, plugins, or just the ability to edit files.